Skip to content

[request]: Amazon FSx for NetApp ONTAP operational review skill #118

Description

@aneeshamz

Select the type of tool this is related to

  • Skill
  • Custom agent
  • MCP server
  • IaC (Infrastructure as Code) template
  • Other

Tell us about your request

A read-only, fully automated operational-review skill for Amazon FSx for NetApp ONTAP (FSxN) that assesses a file system / SVM / volume (or a whole account+region footprint) across Backup, Observability, Operations, Performance, and Security, and returns a prioritized, evidence-based findings report.

Which AWS service(s) is this for?

Amazon FSx for NetApp ONTAP, Amazon CloudWatch, AWS Backup, Amazon EC2

What problem are you trying to solve?

Operators running FSx for NetApp ONTAP have no quick, consistent way to assess the operational posture of their file systems. Doing it by hand means stitching together fsx config, CloudWatch metrics, AWS Backup coverage, and EC2 networking, and knowing FSxN-specific gotchas (e.g. Gen2 file systems don't emit StorageCapacityUtilization; SVM root volumes skew capacity metrics). Without a skill, DevOps Agent gives a generic review that misses these service-specific details and isn't reproducible across prod/pre-prod or across iterations.

How should it behave?

Triggers on requests like "FSxN operational review", "review my FSx ONTAP", "audit my FSxN posture". Self-discovers all ONTAP file systems in the account/region, runs 46 checks across 5 pillars using only public AWS Describe*/List*/Get* calls and CloudWatch metric reads via use_aws, applies evidence guardrails (missing data → "Not evaluated", never a guessed pass/fail), and produces a prioritized findings report keyed to check IDs. Strictly read-only — no Create*/Update*/Delete*, no ONTAP CLI, no manual steps.

Which DevOps Agent functionalities is this relevant to?

Chat tasks, Evaluation

Does this need extra permissions?

Yes — read-only only: fsx:Describe* + fsx:ListTagsForResource, cloudwatch:DescribeAlarms/GetMetricData/GetMetricStatistics/ListMetrics, backup:ListProtectedResources/ListRecoveryPointsByResource, ec2:DescribeSecurityGroups/Subnets/RouteTables. Delivered via the shared
devops-agent-skill-policies.yaml under a new EnableAwsFsxnOperationsReview toggle.

Are you currently working around this?

Manual, service-specific checklists and ad-hoc CloudWatch/console inspection — slow, inconsistent, and not reproducible.

Have you checked for existing tools?

  • I've searched existing issues, skills, custom agents, and MCP servers, and this isn't already covered or extendable.
  • I've confirmed DevOps Agent can't already do this natively (I tested it).

Would you like to build it?

  • I'm willing to contribute this myself (see CONTRIBUTING.md).
  • I'm suggesting it for someone else to build.

Additional context

PR up at #117. Not a duplicate of aws-backup-coverage-review — that reviews account-wide AWS Backup coverage; this is an FSxN-specific review across five pillars.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    iacRelates to an IaC templateneeds-triageNew issue awaiting maintainer triagerequestCommunity request for a new tool (roadmap intake)skillRelates to a DevOps Agent skill

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions